Skip to content
Rietta Cybersecurity·

🚨Ruby on Rails ActiveStorage Vulnerability CVE-2026-66066

Rails devs, patch now or risk remote code execution

TL;DR

A critical vulnerability in Ruby on Rails ActiveStorage was discovered, leading to immediate patches and notifications to impacted clients. The vulnerability, rated 9.5/10 CVSS, was exploited within hours of disclosure.

A severe remote code execution vulnerability in Ruby on Rails ActiveStorage was discovered and patched within hours. The vulnerability, rated 9.5/10 CVSS, was exploited using a malicious BMP file just hours after initial disclosure. The Rails team released a hotfix on July 29, 2026, and notified impacted clients. Continuous probing began on August 3, 2026, using disguised PNG files. The extent of the attacks and the motivation of the attackers remain unclear. This is a critical issue for any Rails app using ActiveStorage, especially those handling user-uploaded files.

Ruby on Rails ActiveStorage Vulnerability CVE-2026-66066 — Rietta Cybersecurity

Key Points

1

Vulnerability discovered in Ruby on Rails ActiveStorage on July 21, 2026

2

CVSS score climbed to 9.5/10 by July 29, 2026, evening

3

Hotfix applied on July 29, 2026, via 'bundle update activestorage rails'

4

First attack occurred at 7:10:25 AM EST on July 30, 2026, using a BMP file

5

Continuous probing began on August 3, 2026, using disguised PNG files

Why It Matters

If you're running a Rails app with ActiveStorage, especially handling user-uploaded files, this vulnerability could be exploited. The patch was released on July 29, 2026, but the first attack happened just hours later. Continuous probing began on August 3, 2026, indicating ongoing threat.

Ruby on RailsActiveStorageCVE-2026-66066patchingexploitation

Frequently Asked Questions

Why does this matter?

If you're running a Rails app with ActiveStorage, especially handling user-uploaded files, this vulnerability could be exploited. The patch was released on July 29, 2026, but the first attack happened just hours later. Continuous probing began on August 3, 2026, indicating ongoing threat.

What happened?

A critical vulnerability in Ruby on Rails ActiveStorage was discovered, leading to immediate patches and notifications to impacted clients. The vulnerability, rated 9.5/10 CVSS, was exploited within hours of disclosure.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,464 builders reading daily.

Also get